Microsoft is hoping to make it tougher to steal Windows passwords

passwords
Windows 11 anti-pishing (Image credit: Shutterstock / vladwel)

A cybersecurity rule sitting in Microsoft’s antivirus program will soon run by default, in a bid to prevent threat actors from stealing Windows credentials

Cybersecurity researcher Kostas first spotted the change in an update to Microsoft’s Attack Surface Reduction (ASR) rules.

Threat actors usually steal credentials or use various exploits in order to move laterally through an already compromised network. One way to go about this business is to get admin access, then dump the memory of the Local Security Authority Server Service (LSASS) process, as it holds NTLM hashes of Windows credentials. 

Driver conflicts

These can later be brute-forced, but in order to keep LSASS memory dumps away from prying eyes, Microsoft prevents access to it, through the Credential Guard, which isolates the process in a virtualized container. 

However, as BleepingComputer notes, the feature sometimes results in driver conflicts on the endpoints, which is why many organizations choose not to enable it. 

Now, to work around this issue, Microsoft will enable an ASR rule, called “Block credential stealing from the Windows local security authority subsystem,” by default. 

It prevents processes from opening the LSASS process, even with admin privileges.

"The default state for the Attack Surface Reduction (ASR) rule “Block credential stealing from the Windows local security authority subsystem (lsass.exe)” will change from Not Configured to Configured and the default mode set to Block. All other ASR rules will remain in their default state: Not Configured.," the updated document reads.

"Additional filtering logic has already been incorporated in the rule to reduce end user notifications. Customers can configure the rule to Audit, Warn or Disabled modes, which will override the default mode. The functionality of this rule is the same, whether the rule is configured in the on-by-default mode, or if you enable Block mode manually. "

 Via: BleepingComputer 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Microsoft is changing the way logins work: here’s what that means for you
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
digital key
Microsoft really wants users to ditch passwords and switch to passkeys
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
AI security shield
The US wants security requirements as standard to stop sensitive data from falling into enemy hands
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
Latest in Security
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Latest in News
Garmin Instinct 3 in Neotropic Green
"I'm an idiot": Garmin user reveals how fixing one setting completely changed their training after months of making no progress
The main battle pass characters in Fortnite Lawless, including Midas, Sub Zero and a large wolf-man
You'll finally be able to play Fortnite on Windows 11 Arm-powered laptops as Epic Games partners with Qualcomm
DeepSeek on an iPhone
OpenAI calls on US government to ban DeepSeek, calling it ‘state-subsidized’ and ‘state-controlled’
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Stress
Complexity of IT systems could be increasing security risks for businesses
Warhammer 40,000: Space Marine 3
Warhammer 40,000: Space Marine 3 enters development as team promises to support Space Marine 2 'with exciting content and regular updates in the coming years'